Trust & Safety

Data Processing Agreement

If you use DiemDesk at work, your organisation is the controller of any personal data involved and we are a processor. GDPR Article 28 says a controller may not use a processor without a contract on these terms. This page sets ours out in plain language — and explains why the list of things we actually process is much shorter than you are used to reading.

Last updated August 2026

Read this part first

This page is a plain-English statement of how we operate, published so a reviewer can assess us quickly. It is not a signed contract and it has not been through outside counsel. If your organisation needs an executed DPA on your own paper, or standard contractual clauses for a transfer, write to [email protected] and say so — that is a normal request and we would rather sign yours than argue about ours.

1. What this covers

It applies where you use DiemDesk in the course of your work and personal data belonging to other people — your clients, your patients, your staff, your candidates — passes through the product. You decide what that data is and why it is being handled; that makes you the controller. We act only on your instructions, which for a self-serve product means: the tool you chose, doing the job you asked it to do.

2. What we actually process

This is the part that differs from most vendors, so it is worth being precise rather than reassuring.

Where it runsDoes your file reach us?What we hold
In-browser tools (most of the catalogue)No. It is opened and rebuilt on your device.Nothing. There is no upload to retain.
Office conversions, OCR, webpage captureYes — they cannot run in a browser.The file, for as long as the conversion takes, then deleted.
AI toolsThe text it needs, not the file.Nothing after the answer is returned.
File VaultYes, but encrypted on your device first.Ciphertext we cannot read. We do not hold the key.
AccountName, email, plan status.

Why the first row matters to a reviewer

Most privacy assurances are retention promises: we received your document and we promise to delete it. That is a promise about our conduct. For the in-browser tools there is no transfer to justify, no retention period to audit and no copy to breach, because the document never arrived. Your Article 30 record has nothing to add for those tools.

3. Our obligations

  • Only on your instructions. We process personal data to provide the tool you used and for nothing else. We do not sell data, we do not build advertising profiles, and we do not train models on your documents.
  • Confidentiality. Anyone with access is bound to keep it confidential.
  • Security. Encryption in transit throughout; encryption at rest for anything stored; end-to-end encryption for File Vault, where the key never leaves your device.
  • Subprocessors. Named below. We tell you before adding one.
  • Helping you answer people. If someone asks you for access, correction or erasure, we will help you respond within the time you have to respond.
  • Breach notice. If personal data we hold is breached, we notify you without undue delay and in any event within 72 hours of becoming aware, with what we know at the time.
  • Deletion. On request, or when you close your account, we delete what we hold. Server-side conversions are already deleted immediately after the job.
  • Audit. We will answer a security questionnaire and provide the information you reasonably need to satisfy Article 28.

4. Subprocessors

Everyone outside DiemDesk who may handle personal data on our behalf. It is a short list, and it is short for a structural reason rather than a modest one — most of the product never sends anything anywhere.

The current list, with what each one is for, is on the subprocessors page. There are 4.

5. Where data goes

DiemDesk is operated from the United States and our servers are in the United States. Where a transfer of personal data out of the UK or EEA takes place, it is made on the basis of the appropriate safeguards available to us at the time, and we will complete standard contractual clauses on request. Server-side work is transient in every case: a conversion runs and the file is deleted.

6. How long this lasts

For as long as you use DiemDesk. When you stop, we delete the personal data we hold unless we are required to keep something — payment records exist because tax law says they must, and they sit with our payment processor rather than with us.

Signing something on your paper

Legal, healthcare, financial and HR teams frequently cannot buy without an executed DPA, and often have their own template they would rather use. Send it to [email protected]. Related reading: Privacy, Security, Subprocessors, Terms.

Check it yourself

Every claim about the in-browser tools is verifiable in thirty seconds. Open a tool, open your browser’s Network tab, and process a file. No request carries it. That is the kind of assurance a questionnaire cannot give you and a Network tab can.

Contact

Data protection enquiries: [email protected]